CWE-497— Exposure of Sensitive System Information to an Unauthorized Control Sphere
308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-497page 1 of 7
- CVE-2018-25358HIGHCVSS 7.5EG 7.52026-05-23
D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST requests. Attackers can send requests to /m…
- CVE-2019-10243MEDIUMCVSS 5.3EG 5.32019-04-09
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifically craft attacks to the web server run by Kura.
- CVE-2019-25228MEDIUMCVSS 5.3EG 5.32025-12-18
An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to ex…
- CVE-2019-25230MEDIUMCVSS 4.3EG 4.32025-12-18
An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system…
- CVE-2020-25179CRITICALCVSS 9.8EG 9.82020-12-14
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
- CVE-2020-26076HIGHCVSS 7.5EG 7.52020-11-18
A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on an affected device. The vulnerability is due to the absence of authentication for sensitive…
- CVE-2020-36922HIGHCVSS 7.5EG 7.52026-01-06
Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server…
- CVE-2020-36926HIGHCVSS 7.5EG 7.52026-01-16
SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve a…
- CVE-2021-0260HIGHCVSS 7.3EG 7.32021-04-22
An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able to perform SNMP read actions, an Exposure of System Data to …
- CVE-2021-0291MEDIUMCVSS 6.5EG 6.52021-07-15
An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-level resource is not being sufficiently protected, allows a network-based unauthenticated attacker to send specific traff…
- CVE-2021-1234MEDIUMCVSS 5.3EG 5.32024-11-18
A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the vManag…
- CVE-2021-1235MEDIUMCVSS 5.5EG 5.52021-01-20
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read sensitive database files on an affected system. The vulnerability is due to insufficient user authorization. An attacker could…
- CVE-2021-1535MEDIUMCVSS 5.3EG 5.32021-05-06
A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the Cisco SD-WA…
- CVE-2021-1544MEDIUMCVSS 5.5EG 5.52021-06-04
A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An atta…
- CVE-2021-23135MEDIUMCVSS 5.9EG 5.92021-05-12
Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versi…
- CVE-2021-31955MEDIUMCVSS 5.5EG 9.0⚠ KEV2021-06-08
Windows Kernel Information Disclosure Vulnerability
- CVE-2022-1902HIGHCVSS 8.8EG 8.82022-09-01
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secre…
- CVE-2022-20664HIGHCVSS 7.7EG 7.72022-06-15
A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve s…
- CVE-2022-20734MEDIUMCVSS 4.4EG 4.42022-05-04
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacke…
- CVE-2022-2403MEDIUMCVSS 6.5EG 6.52022-09-01
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or servi…
- CVE-2022-28651HIGHCVSS 8.4EG 5.52022-04-05
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
- CVE-2022-34458MEDIUMCVSS 6.6EG 5.52023-02-01
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user coul…
- CVE-2022-38710MEDIUMCVSS 5.3EG 5.32022-11-03
IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in further attacks against the system. IBM X-Force ID: 234292.
- CVE-2022-4366HIGHCVSS 7.5EG 7.52022-12-08
Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.
- CVE-2022-43852MEDIUMCVSS 5.3EG 5.32025-04-14
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.
- CVE-2022-4968MEDIUMCVSS 6.5EG 6.52024-06-07
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.
- CVE-2022-4985HIGHCVSS 8.7EG 0.02025-11-14
Vodafone H500s devices running firmware v3.5.10 (hardware model Sercomm VFH500) expose the WiFi access point password via an unauthenticated HTTP endpoint. By sending a crafted GET request to /data/activation.json with specific headers and…
- CVE-2022-50237MEDIUMCVSS 5.9EG 5.92025-07-28
The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.
- CVE-2023-0005MEDIUMCVSS 4.1EG 4.92023-04-12
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
- CVE-2023-0342LOWCVSS 3.1EG 3.12023-06-09
MongoDB Ops Manager Diagnostics Archive may not redact sensitive PEM key file password app settings. Archives do not include the PEM files themselves. This issue affects MongoDB Ops Manager v5.0 prior to 5.0.21 and MongoDB Ops Manager v6.0…
- CVE-2023-20111MEDIUMCVSS 6.5EG 6.52023-08-16
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive …
- CVE-2023-23472LOWCVSS 3.1EG 3.12024-12-11
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
- CVE-2023-2541MEDIUMCVSS 5.3EG 5.32023-06-07
The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about the application such as versions, host names, or IP addresses. No personal information or application data was exposed.
- CVE-2023-32550CRITICALCVSS 9.3EG 9.32023-06-06
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
- CVE-2023-34209MEDIUMCVSS 5.0EG 5.02023-10-17
Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to obtain the absolute path via unencrypted VIEWSTATE p…
- CVE-2023-37487MEDIUMCVSS 5.3EG 5.32023-08-08
SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which could lead to high impact on confidentiality with no impact on…
- CVE-2023-37525MEDIUMCVSS 5.3EG 5.32026-01-28
A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to applicati…
- CVE-2023-41366MEDIUMCVSS 5.3EG 5.32023-11-14
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, …
- CVE-2023-42010LOWCVSS 3.1EG 3.12024-07-17
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507.
- CVE-2023-4237HIGHCVSS 7.3EG 6.52023-10-04
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromis…
- CVE-2023-4605MEDIUMCVSS 6.5EG 6.52024-04-05
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
- CVE-2023-50180MEDIUMCVSS 5.5EG 5.52024-05-14
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below m…
- CVE-2023-5081LOWCVSS 3.3EG 3.32024-01-19
An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettable device identifier.
- CVE-2023-50959MEDIUMCVSS 5.3EG 5.32024-03-31
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 23.0.1, and 23.0.2 may allow end users to query more documents than expected from a connect…
- CVE-2024-0053LOWCVSS 3.3EG 3.32024-03-11
In getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interac…
- CVE-2024-10240MEDIUMCVSS 5.3EG 5.32024-11-26
An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to…
- CVE-2024-10940MEDIUMCVSS 5.3EG 5.32025-03-20
A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.promp…
- CVE-2024-11029MEDIUMCVSS 5.5EG 5.52025-01-15
A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the ad…
- CVE-2024-11035LOWCVSS 2.5EG 2.52025-03-05
Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a type of issue whereby sensitive information may b exposed due to a vulnerability in software.
- CVE-2024-12367HIGHCVSS 8.6EG 8.62025-09-16
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Master allows Directory Indexing. This issue affects Vega Master: from v.1.12.35 through 20250916. NOTE: The vendor did …
Map vulnerabilities like CWE-497 to your infrastructure
EchelonGraph correlates every CVE — across CWE-497 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →